Page 22 of 151 results (0.007 seconds)

CVSS: 7.5EPSS: 0%CPEs: 10EXPL: 0

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. IBM WebSphere Application Server (WAS) 8.5 hasta la versión 8.5.5.9 Liberty hasta la versión Liberty Fix Pack 16.0.0.2 no incluye el indicador HTTPOnly en una cabecera Set-Cookie para una cookie JAX-RS API no especificada, lo que facilita a atacantes remotos obtener información potencialmente sensible a través de secuencias de comandos de acceso a esta cookie. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI61936 http://www-01.ibm.com/support/docview.wss?uid=swg21983700 http://www.securityfocus.com/bid/91518 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 61EXPL: 0

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. Vulnerabilidad de inyección CRLF en IBM WebSphere Application Server (WAS) 7.0 en versiones anteriores a 7.0.0.43, 8.0 en versiones anteriores a 8.0.0.13, 8.5 Full en versiones anteriores a 8.5.5.10 y 8.5 Liberty en versiones anteriores a Liberty Fix Pack 16.0.0.2 permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y llevar a cabo ataques de separación de respuesta HTTP a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI58918 http://www-01.ibm.com/support/docview.wss?uid=swg21982526 http://www.securityfocus.com/bid/91484 http://www.securitytracker.com/id/1036184 •

CVSS: 5.9EPSS: 0%CPEs: 49EXPL: 0

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors. IBM WebSphere Application Server (WAS) 7.0 en versiones anteriores a 7.0.0.41, 8.0 en versiones anteriores a 8.0.0.13 y 8.5 en versiones anteriores a 8.5.5.10, cuando FIPS 140-2 está activado, configura incorrectamente TLS, lo que permite a atacantes man-in-the-middle obtener información sensible a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI56190 http://www-01.ibm.com/support/docview.wss?uid=swg21979231 http://www.securityfocus.com/bid/85978 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 9EXPL: 0

Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la aplicación web del cliente OpenID Connect (OIDC) en IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 en versiones anteriores a 8.5.5.9 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI58003 http://www-01.ibm.com/support/docview.wss?uid=swg21978293 http://www.securitytracker.com/id/1035330 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 47EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider. Vulnerabilidad de XSS en IBM WebSphere Application Server 7.0 en versiones anteriores a 7.0.0.41, 8.0 en versiones anteriores a 8.0.0.12 y 8.5 en versiones anteriores a 8.5.5.9 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de datos de un proveedor OAuth manipulados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI49272 http://www-01.ibm.com/support/docview.wss?uid=swg21974520 http://www.securityfocus.com/bid/81738 http://www.securitytracker.com/id/1034783 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •